This Privacy Policy explains how Valarchy Labs LLP (LLPIN ACV-7063), a limited liability partnership registered in India (“Moduvanta”, “we”, “us”), handles personal data in connection with the Moduvanta learning-management platform at moduvanta.com and its workspace subdomains and custom domains (the “Service”).
1. Controller and processor roles
Moduvanta is multi-tenant. Each institution that creates a workspace (a “Customer”) decides what learner and staff data to put into its workspace and for what purpose. For that workspace content, the Customer is the data controller and Moduvanta acts as a processor on the Customer’s instructions.
Moduvanta is the controller for data it needs to run the Service itself — account records for the person who signs up, billing records, security and audit logs, and website analytics.
If you are a learner or staff member added to a workspace by your institution, direct requests about your data to that institution first; we will support them in responding.
2. What we collect and why
Account & identity
- Workspace owner (Super Admin): name, email address, and a hashed password (bcrypt — we never store the plaintext), collected at signup to create and secure the account.
- Staff and learners: name, email address, an optional hashed password, and free-form tags — added by a workspace’s admins so those people can be enrolled and tracked.
- Google sign-in (optional, if an institution enables it): your Google account identifier and the email/name Google returns, used only to authenticate you.
Institution & workspace
- Institution name, institution type, chosen subdomain, and any custom domain.
- Workspace settings — theme, terminology, sign-in methods, plan.
Learning activity
- Courses, lessons, and quizzes created in the workspace.
- Enrolments, completion status and dates, learning-path progress, and quiz attempts and scores.
- Audit logs and automation-run history (who did what, and which automated enrolment / compliance-flag actions ran).
Billing
- Plan, subscription status, and billing identifiers. Card and bank details are entered directly with our payment processors and are not stored on Moduvanta’s systems. See section 6.
Technical
- Standard server and request logs from our hosting providers (IP address, user-agent, timestamps, request paths) for security, debugging, and abuse prevention.
- A single essential session cookie,
mv_session(httpOnly), to keep you signed in. Website analytics are aggregate and cookie-less. We do not use advertising or cross-site tracking cookies.
3. How we use data
- To provide, secure, and support the Service.
- To authenticate users and enforce workspace and role boundaries.
- To send transactional email (sign-in, provisioning, and automation notifications configured by a workspace admin).
- To take payment and manage subscriptions.
- To investigate abuse, enforce our Terms, and meet legal obligations.
- To understand aggregate product usage and improve the Service.
We do not sell personal data, and we do not use workspace content to train machine-learning models.
4. Where data is hosted
The primary database and file storage are in India (AWS Asia Pacific — Mumbai, ap-south-1), via Supabase. The web application runs on Vercel with server compute in the Mumbai (bom1) region and a global edge network for static content. A backend API service runs on Render in Singapore. Transactional email is sent via Resend, and payments are processed by Razorpay and Stripe (see section 6). Some of these providers process limited data (request metadata, email content, payment details) outside India. By using the Service you acknowledge these transfers; we rely on the providers’ contractual data-protection commitments.
5. Third-party processors
These providers process personal data on our behalf to run the Service:
| Processor | Purpose | Data involved |
|---|---|---|
| Supabase | Managed database, file storage, auth infrastructure (India region) | All workspace and account data |
| Vercel | Web application hosting, CDN, aggregate analytics | Request logs, IP/user-agent, page-view counts |
| Render | Backend API hosting (Singapore) | Request logs; data in transit for API calls |
| Resend | Transactional email delivery | Recipient name and email, message content |
| Razorpay | Payments (primary, India and international) | Name, email, billing details, payment instrument (held by Razorpay) |
| Stripe | Payments (international, where applicable) | Name, email, billing details, payment instrument (held by Stripe) |
| OAuth sign-in — only if an institution enables it | Google account identifier, email, name |
We will keep this list current. Material changes to processors handling significant volumes of personal data will be reflected here with an updated date.
6. Payment handling
When billing is enabled, payments are collected and processed by Razorpay (an RBI-authorised payment aggregator) and, for some international transactions, Stripe. You enter card, UPI, or bank details directly with the processor; Moduvanta receives only a token, the transaction result, and subscription metadata. Card data never touches Moduvanta’s servers. The processors are independent controllers for the payment data they collect and apply their own privacy terms and PCI-DSS controls. International card payments may involve currency conversion and cross-border processing by the payment provider.
7. Retention
- Workspace content (users, courses, quiz scores, enrolments, logs) is retained for as long as the workspace is active, and is deleted when the workspace is deleted or on a Customer’s documented instruction.
- Account and billing records are retained while the account is active and for a limited period afterwards to meet tax, accounting, and legal-defence obligations.
- Security and server logs are retained for a short rolling window (typically weeks) unless needed for an active investigation.
- Backups are retained on a rolling schedule; data deleted from the live system is purged from backups as they age out.
Specific retention periods are being finalised as part of our data- governance work (see section 8) and will be stated precisely here.
8. Your rights: access, export, correction, deletion
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. India’s Digital Personal Data Protection Act, 2023 provides rights of this kind to individuals in India.
A self-service data export and deletion flow is in development (planned as Phase 5.2). Until it ships:
- If your data lives in an institution’s workspace, ask that institution’s admin — they can edit or remove your record directly.
- For account-level data, or if the institution cannot help, email privacy@moduvanta.com. We will verify your identity and respond within a reasonable period consistent with applicable law.
9. Security
Passwords are hashed with bcrypt. Access to workspace data is enforced at the database level with row-level security scoped to each tenant. Connections use TLS. Access to production systems is limited to personnel who need it. No system is perfectly secure; we cannot guarantee absolute security, and you are responsible for keeping your credentials safe.
10. Children
The Service is intended for institutions and their staff and learners, not for direct use by children. Where an institution uses Moduvanta to train minors, that institution is responsible for obtaining any consent required by law and for the lawful basis of that processing.
11. Changes to this policy
We may update this policy as the Service and our processors change. The “last updated” date at the top reflects the latest version. Material changes will be communicated to workspace owners by email or an in-app notice.
12. Contact
Valarchy Labs LLP (LLPIN ACV-7063), India. Privacy enquiries: privacy@moduvanta.com.
This document is a starting draft prepared without legal advice and has not been reviewed by a lawyer. It must be reviewed by qualified counsel — with particular attention to cross-border payments and multi-jurisdiction data-protection obligations — before it is relied on.